| Hi I cannot get the universal forwarder to move to active mode. I get the following error in splunkd logs. Can you... by RuthBishop New Member in Getting Data In 05-08-2014 0 3 | 0 | 3 | ||
| hello I am trying to extract a field and change the value of source for apache logs. The source comes as /tmp/usr/... by theouhuios Motivator in Getting Data In 05-08-2014 0 8 | 0 | 8 | ||
| Hey, I am monitoring some Windows Event Log data and I want to see from this any events where the 'startup type' is ... by Ant1D Motivator in Getting Data In 05-08-2014 0 1 | 0 | 1 | ||
| I have a network where I have a splunk instance that is off to the side on my network, as in: Core Splunk Instance (... by jmsiegma Path Finder in Getting Data In 05-07-2014 1 2 | 1 | 2 | ||
| I installed the splunkforwarder on a few machines, and added /var/log as a syslog source. I overlooked the fact that... by tinkster Explorer in Getting Data In 05-07-2014 0 4 | 0 | 4 | ||
| The Splunk software matrix doesn't mentioned support for Windows Server 2012 R2. What versions of Splunk and the Uni... by hornslethk Engager in Getting Data In 05-07-2014 4 17 | 4 | 17 | ||
| I've run back and forth through the props.conf documentation and done a few circuits of Answers, but I haven't found ... by willial Communicator in Getting Data In 05-07-2014 0 5 | 0 | 5 | ||
| Okay, so here is my situation: I am running a Splunk for Window Enterprise Server along with a separate OSSEC server ... by ceichhorn Engager in Getting Data In 05-07-2014 0 4 | 0 | 4 | ||
| Is there any capability within Splunk so it automatically deletes the Application, Security, and System Logs in Event... by sysadmin74 New Member in Getting Data In 05-07-2014 0 3 | 0 | 3 | ||
| What are the steps to setup a new CA and generate new certs for SSL forwarding with no auth: by matt Splunk Employee 0 4 | 0 | 4 | ||
| I am writing a Windows Security Log search for user accounts and have the eventID I need to search for but the result... by kluey Explorer in Getting Data In 05-06-2014 0 2 | 0 | 2 | ||
| Hi Team, I have a folder by name Mumbai under C drive with subfolders in it. If i edit the inputs.conf file as mon... by sushma7 Path Finder in Getting Data In 05-06-2014 1 20 | 1 | 20 | ||
| Guys, I'm trying to index some Syslog data from some F5's. The issue I have is, Splunk seems to recognize and break ... by salles Loves-to-Learn Lots in Getting Data In 05-05-2014 0 1 | 0 | 1 | ||
| We are running searchhead pooling and have many indexers. I would like to be able to find out how long it takes for ... by rmorlen Splunk Employee 0 3 | 0 | 3 | ||
| Hi Guys, I'm trying to break events in Splunk with a text file with just ip addresss in it and no time stamps. The f... by tbalouch Path Finder in Getting Data In 05-05-2014 0 2 | 0 | 2 | ||
| I am using the DB Connect app to connect to a MYSQL database and input the data from a table. the datetime fields in... by hylee Explorer in Getting Data In 05-05-2014 0 4 | 0 | 4 | ||
| I have McAfee logs that contain going into Splunk and the event time is populated with the time that the event is act... by digital_alchemy Path Finder in Getting Data In 05-05-2014 0 3 | 0 | 3 | ||
| Hi, I tried props.conf and transforms.conf solution but it did not work. props.conf [access_combined] pulldown_ty... by safe_splunk Explorer in Getting Data In 05-05-2014 0 6 | 0 | 6 | ||
| we have multiple files that are being monitored ; file.1, file.2, file.3 Bob.1, Bob.2, Bob.3, Cat.1 Cat.2, Cat3. ...e... by d646800 Explorer in Getting Data In 05-04-2014 0 2 | 0 | 2 | ||
| Hello All, i am struggling with my db-dump input in loading data from db query to index. I have defined the db input ... by linu1988 Champion in Getting Data In 05-03-2014 0 1 | 0 | 1 | ||
| Have a clustered environment of 3 indexers. Data in the indexers was used to test full architecture capability. don... by cirkit1 Explorer in Getting Data In 05-03-2014 1 1 | 1 | 1 | ||
| Hi All, I have log files in directory structure like this: /var/log/data/index-a/logfile1.log /var/log/data/index-... by mahesh_ravji1 Explorer in Getting Data In 05-01-2014 0 2 | 0 | 2 | ||
| hey! i want to monitor php. at the moment i use splunk-6.0.2-196940-x64-release. so for this goal i did the followin... by jimmyfallon New Member in Getting Data In 05-01-2014 0 11 | 0 | 11 | ||
| Hi, I should know this at this point, but want to confirm... Is a restart of the indexer required if an updated prop... by a212830 Champion in Getting Data In 05-01-2014 0 3 | 0 | 3 | ||
| Hey There, I have a list of 150 servers which listed in a csv file (lookup table). Here's my current search earliest ... by Raghav2384 Motivator in Getting Data In 05-01-2014 1 6 | 1 | 6 |